Skip to content

US aviation comms lack sufficient cyber protections, says GAO

FAA is aware of cybersecurity issues but yet to implement full fixes, warn auditors.

US aviation comms lack sufficient cyber protections, says GAO
Image Credit: https://unsplash.com/@chuklanov

Poor cybersecurity in the US Federal Aviation Administration is putting aircraft communication channels at risk of attack, government auditors have warned.

The same day an accidental cable cut knocked telecommunication equipment offline on the US East Coast, the US Government Accountability Office (GAO) said issues with authentication, encryption, and protocol design risked causing similar incidents.

A GAO report on aviation cybersecurity said communications through the FAA’s two text-based applications, ACARS and CPDLC, were “generally not encrypted and lack authentication… [and] vulnerable to interception, spoofing, and flood-based denial-of-service attacks.”

Investigators said the organisation had partially addressed some of GAO’s prior cybersecurity concerns and identified cybersecurity threats to the national airspace (NAS), but “has not fully implemented key elements of a risk-based cybersecurity program.”

Unsupported systems

This content is for members only

Subscribe
Add The Stack on Google